CVE-2014-3629: Apache Qpid

Medium severity, CVSS 4.3. EPSS: 6.9% chance of exploitation in the next 30 days.

XML external entity (XXE) vulnerability in the XML Exchange module in Apache Qpid 0.30 allows remote attackers to cause outgoing HTTP connections via a crafted message.

Affected products

  • Apache Qpid: version 0.30 only

Published 2014-11-17. Last modified 2026-06-17.